Impact
An SQL injection flaw in the processing of NVBUDashboard JSON-RPC messages allows an attacker to inject malicious SQL that ultimately leads to execution of arbitrary code in the context of NETWORK SERVICE. While authentication is nominally required, the existing authentication mechanism can be bypassed, meaning that a remote attacker can supply a crafted request and execute code on the target system. The vulnerability stems from insufficient validation of a user‑supplied string before its use in database queries, a classic input‑validation weakness described by CWE‑89.
Affected Systems
Quest NetVault Backup installations are affected. No specific version information is provided in the CVE record, so all currently installed and supported instances of Quest NetVault Backup may be vulnerable until an official patch or fix is applied.
Risk and Exploitability
The CVSS base score of 8.8 indicates a high severity risk. The EPSS score is not available, so the current likelihood of exploitation in the wild cannot be quantified, but the vulnerability is listed in the Zero Day Initiative advisory ZDI‑26‑368, demonstrating that exploits have been examined. The weakness is remote with authentication bypass, so an attacker can target the NVBUDashboard service over the network, submit a malicious JSON‑RPC payload, and cause code execution at the SYSTEM level. The flaw is not yet catalogued in CISA’s KEV list, but the potential impact warrants immediate attention.
OpenCVE Enrichment